MindPaya · Legal
MindPaya Privacy Notice
This notice explains what personal data AnyPaya Oy processes when you use MindPaya or visit anypaya.ai, why, where it is kept, who else handles it and what rights you have. It applies together with the MindPaya Terms of Service.
1. Who is responsible
AnyPaya Oy, business ID 3640857-7, registered office in Helsinki, Finland (“AnyPaya”, “we”), provides MindPaya and the AnyPaya ID sign-in service and publishes the website anypaya.ai. You can reach us about this notice at support@anypaya.ai.
2. Two roles: your account, and your organization’s content
MindPaya is used by organizations. Personal data appears in it in two ways, and our role differs between them.
- Your account and your use of the Service. When you sign in, are invited to an organization, or write to us, we decide how that data is processed. For this data AnyPaya is the controller, and Sections 3 to 12 apply directly.
- Content your organization stores. Memories, notes, connected Slack channels, documents and the summaries MindPaya derives from them belong to the organization that stored them (the customer). The customer decides what goes in and who can see it. For personal data in that content AnyPaya is a processor acting on the customer’s instructions, and the customer is the controller. Section 4 explains what that means for you, and the data processing terms in Section 12 of the Terms of Service bind us towards the customer.
3. Personal data we process as controller
Account and sign-in
You sign in through AnyPaya ID with a Google account. We receive and store your name, email address and the identifier of your Google account, and, if Google provides it, a link to your profile picture. AnyPaya ID keeps your organization memberships and your role in each organization (owner, admin or member). MindPaya stores your email address as the identity that acts in the Service.
Session and security data
When you use the Service we process session identifiers, your IP address, browser type and version, request timestamps, sign-in and sign-out events and which organization you signed in to. During a free period the Service records which people hold the organization’s places.
Activity and audit records
The Service keeps an audit trail of administrative actions: who created the organization and which version of the terms they accepted, who invited, changed or removed a member, who created or revoked API keys and connection codes, who connected or disconnected a source and who changed settings. If an AnyPaya operator opens your organization to give support, that access is logged and shown to your organization’s administrators.
Support and correspondence
When you write to support@anypaya.ai or hello@anypaya.ai we process your name, email address and the content of the correspondence to answer you.
Billing
When an organization moves to a paid plan we process the company details and the invoicing contact you give us. We do not store payment card data; if a payment service is used, card data is entered directly with that service.
Website
anypaya.ai uses no analytics or advertising trackers. Our web server keeps technical logs (IP address, requested page, time, browser type) for security and troubleshooting.
4. Content your organization stores in MindPaya
Your organization and its AI assistants store content in MindPaya: notes, memories, decisions and content read from sources the organization connects, such as Slack channels, code repositories or documents. That content may contain personal data about you and about other people, such as names, messages and opinions. MindPaya derives summaries, relations and maps from it within the organization.
The organization is the controller of this content. We process it only to provide the Service to that organization and on its instructions. We do not use it to train machine-learning models, we do not sell it and we do not share it with other customers. MindPaya itself does not send it to AI model providers; what your organization’s assistants do with content they recall is under the organization’s control.
If you want content about you in an organization’s MindPaya corrected or removed, contact that organization’s administrator first; the Service gives administrators tools to edit, redact and erase content, including removing a participant from imported conversations. We help the organization with such requests and forward requests we receive to it.
5. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Signing you in, keeping your session and showing you the organizations you belong to | Account, sign-in and session data | Performance of the contract with the customer you act for (6(1)(b)); our legitimate interest in providing the Service to that customer (6(1)(f)) |
| Enforcing the free period’s user and workspace limits and paid plans | Sign-in events, place claims, billing data | Performance of the contract (6(1)(b)) |
| Security, preventing abuse, investigating incidents and keeping an audit trail of administrative actions | Session, security and audit data | Legitimate interest in the security and accountability of the Service (6(1)(f)) |
| Answering your questions and providing support | Correspondence | Performance of the contract; legitimate interest in answering the people who contact us (6(1)(b), 6(1)(f)) |
| Invoicing and accounting | Billing data | Performance of the contract; legal obligation under the Finnish Accounting Act (6(1)(b), 6(1)(c)) |
| Informing owners and administrators about changes to the Service or these documents | Email address, role | Performance of the contract; legitimate interest (6(1)(b), 6(1)(f)) |
| Marketing to existing customers | Email address, organization | Legitimate interest in business-to-business communication; you can object at any time (6(1)(f)) |
We do not send marketing to people who have no relationship with us without their consent, and every marketing message tells you how to opt out.
6. Where data is stored and who processes it
MindPaya runs in the European Union. The following companies process personal data on our behalf as sub-processors:
| Sub-processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Servers for MindPaya and AnyPaya ID, object storage for encrypted backups, web hosting for anypaya.ai | Helsinki, Finland |
| Aiven Oy, Helsinki, Finland | Managed PostgreSQL database for MindPaya | Google Cloud region europe-north1, Hamina, Finland |
| Google Ireland Limited (and Google LLC) | Sign in with Google: authentication of your Google account when you sign in through AnyPaya ID | European Union; see Section 7 |
Sources your organization connects, such as Slack, GitHub or Google Drive, send content to MindPaya under the authorization your organization grants them. They are your organization’s service providers under their own terms, not our sub-processors.
We may also disclose personal data to our professional advisers bound by confidentiality, and to authorities where the law requires it. We tell the customer of an intended change to this list at least 30 days in advance, as agreed in the Terms of Service.
7. Transfers outside the EU
We store and process personal data in Finland and elsewhere in the European Union. The one exception is sign-in: when you sign in with Google, Google authenticates you under its own terms, and Google LLC in the United States may take part in that processing. Google LLC is certified under the EU–U.S. Data Privacy Framework, and Google’s terms also provide the European Commission’s standard contractual clauses. We make no other transfers outside the European Economic Area.
8. How long we keep data
- Account and membership data: for as long as you belong to at least one organization in MindPaya. When you are removed from your last organization, or an organization is deleted, its data about you is deleted with it.
- Organization data, including content and audit records: for as long as the organization exists, and for 30 days after it is deleted; backups containing it are deleted within a further 30 days. Audit records that the customer or the law requires us to keep longer are kept for that period.
- Session and server logs: for a limited time for security and troubleshooting, after which they are deleted or made anonymous.
- Correspondence: for as long as needed to handle the matter and to show what was agreed.
- Billing records: for the period the Finnish Accounting Act requires.
9. Cookies and browser storage
MindPaya sets one strictly necessary cookie that keeps you signed in; it is deleted when you sign out or when it expires. AnyPaya ID sets its own sign-in cookies for the same purpose. Your theme preference is kept in your browser’s local storage and never leaves your browser. Neither MindPaya nor anypaya.ai uses advertising or analytics cookies, and we do not track you across other websites.
10. Security
We protect personal data with measures appropriate to the risk:
- all traffic to MindPaya, AnyPaya ID and anypaya.ai is encrypted in transit (TLS);
- the Service is hosted with the EU-based providers listed in Section 6, and the database is a managed service with encryption at rest;
- access to production systems is limited to named AnyPaya personnel who need it, uses personal keys and is logged;
- every organization’s content is isolated from other organizations’ content in the Service, and operator access to a customer’s organization is logged and visible to that customer;
- backups are taken automatically, stored with our EU providers and deleted on a fixed schedule;
- we notify affected customers without undue delay after becoming aware of a personal data breach, and the supervisory authority when the GDPR requires it.
11. Automated decisions and AI
We make no decisions about you that are based solely on automated processing and have legal or similarly significant effects. MindPaya produces memories and summaries from your organization’s content automatically and shows their origin so that people can check them; this happens inside the organization and is not profiling of you by AnyPaya. We do not use personal data or customer content to train machine-learning models.
12. Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive the data you gave us in a portable form, and to withdraw a consent you have given without affecting processing done before the withdrawal. Where we rely on legitimate interest, including for marketing, you can object at any time.
To exercise these rights for data we control, write to support@anypaya.ai. We answer within one month. For content stored by an organization (Section 4), contact that organization’s administrator; we assist the organization and forward requests we receive to it.
You also have the right to lodge a complaint with a supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
13. Children
MindPaya is a service for organizations and is not directed at children. People who use it must be at least 18 years old. If you believe a child has created an account, tell us at support@anypaya.ai and we will remove it.
14. Changes to this notice
We update this notice when our processing changes. Each version has a version number and an effective date, shown at the top of the page. We tell the owners and administrators of customer organizations about material changes by email or in the Service at least 30 days before they take effect.
15. Contact
AnyPaya Oy, business ID 3640857-7, Helsinki, Finland · support@anypaya.ai